Security Trust Center

Review the production boundary before agents scale

This Trust Center summarizes the current Duale AI security, privacy, hosting, and review-input posture for teams evaluating production AI agents.
Review subprocessors

Current status

This is a product posture page, not a certification claim. It separates available controls, review artifacts, and roadmap work.
  • Available today

    Managed customer application data is hosted in Germany by Hetzner. Duale AI is a French company. The current posture describes tenant isolation, access controls, audit events, scoped retention, and subprocessors for the managed service.

  • Review artifacts

    Security questionnaire answers, architecture notes, data-processing agreement request path, subprocessor list, hosting description, incident contact, and product-control summary can be requested during review. Availability depends on current artifact status and review scope.

  • Certification status

    Duale AI does not currently claim SOC 2, SOC 3, ISO 27001, EU AI Act certification, or equivalent certification. Readiness work is not presented as a completed audit.

  • No unsupported badges

    There is no public SOC 3 PDF, EU AI Act certification, or EU Cloud Code of Conduct adherence claim today. Those labels will appear only after the underlying audit or adherence work is complete.

Document map

The buying review usually needs the same documents. Use this map to ask for the right artifact.
  • Data-processing agreement

    The data-processing agreement request path is available during procurement review. The legal pages remain the public source for privacy and processor notices.

  • ISO 27001 roadmap

    ISO 27001 readiness work is not presented as certification.

  • EU residency map

    Managed application data is hosted in Germany today. Website delivery and network protection use Cloudflare edge services.

  • Model provider card

    Customers select and contract with model providers during deployment review. Duale AI treats model routing as configurable infrastructure, not as a hidden bundled provider.

  • AI Act references

    Review inputs can support discussion of logging, transparency, risk management, and human oversight references where those obligations apply. This is not an EU AI Act compliance certification.

Controls that matter for production agents

The platform is designed around stable agent contracts, operational events, and requestable review inputs. Audit exists because production needs it, not as the product category.
  • Track routed work

    Submitted work, errors, retries, and routing decisions can be recorded as operational events so teams can understand what happened without reconstructing the workflow from application logs.

  • Separate tenants and providers

    Customer context is scoped by tenant. Model providers are selected in the customer deployment and treated as replaceable infrastructure.

  • Keep project review explicit

    Teams can document risk thresholds, stop paths, and project-specific review requirements around agent work that carries business or security risk.

  • Limit data movement

    Managed application data is hosted in Germany today. Model-provider traffic depends on the providers selected by the customer and the contracts attached to that choice.

  • Review failures

    Timeouts, rejected calls, degraded providers, and failed work can be made visible as product events where the integration captures them, instead of staying hidden inside one-off scripts or notebooks.

  • Preserve an exit path

    Stable input and output contracts make it easier to move models, policies, and deployment targets without rewriting each agent from scratch.

Data processing posture

The legal pages remain the source of truth for contractual privacy and subprocessor details.
  • Model providers

    Customers choose and contract directly with model providers. Duale AI does not impose a single model provider as a hidden subprocessor.

  • Training-use boundary

    Training-use commitments are governed by the privacy notice, customer agreements, and selected model-provider contracts. Confirm the exact scope during security review.

Contact paths

Use the channel that matches the review question.

Security review questions

Review the production boundary before agents scale.

Review subprocessors